GHSA-v2p7-4pv4-3wwh
MODERATECVE-2025-59036A bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully.
- Affected
- < 1.3.9
- Fixed in
- 1.3.9
- Weakness
- CWE-298
- Published
- 2025-09-10
- Source
- github